DisclosureLens
HackingHealthcareHealthcareSupply Chain (3P Vendor)Business Associate (HIPAA)Customer Data InvolvedPHIHealth (basic)Identity (basic)LowContained

Health Services Agency

bd_67348f2bdea69711 · schema v1 · pii pii-v1

Severity

Low

Discovered

Dec 18, 2025

Filed

Jul 31, 2026

To disclose

32 weeks

Affected

Not disclosed

Confidence

65%
Full breach record for Health Services Agency

Stanislaus County Health Services Agency reported a data breach involving protected health information (PHI) of its patients. The incident occurred at Aesto, LLC, a third-party vendor providing healthcare data migration and archiving services. Between December 2 and December 18, 2025, an unauthorized actor accessed PHI stored on Aesto's AWS infrastructure. The breach was discovered on December 18, 2025. Affected data includes full names and other health-related information. The agency notified the California Attorney General and affected individuals, offering identity theft protection services.

California clockDiscovered Dec 18, 2025Notified Jul 10, 2026204d CA 60-day late32 weeks discovery → filing

Incident timeline

undetected · 16 days
discovery → filing · 32 weeks / 225 days

Dec 2, 2025

Begins

Dec 18, 2025

Discovered

Jul 31, 2026

Filed

vs. sector median

+20 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.